CVE-2026-81896 | Concrete CMS up to 9.5.2 Form Block legacy.php cross site scripting

SecurityVulns

A vulnerability, which was classified as problematic, has been found in Concrete CMS up to 9.5.2. The affected element is an unknown function of the file concrete/single_pages/dashboard/reports/forms/legacy.php of the component Form Block. This manipulation causes cross site scripting.

This vulnerability is tracked as CVE-2026-81896. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More